Microsoft Designing and Implementing Microsoft Azure Networking Solutions (AZ-700 Korean Version) - AZ-700 Korean Exam Practice Test

Azure 구독에 VNet1이라는 가상 네트워크가 있습니다. VNet1에는 Subnet1이라는 서브넷이 있습니다.
서브넷1에 VM1이라는 이름의 가상 머신을 생성합니다. VM1은 사설 IP 주소만 가지며 TCP 포트 443에서 수신 대기하는 App1이라는 웹 애플리케이션을 포함합니다.
기본 규칙 집합을 가진 NSG1이라는 네트워크 보안 그룹(NSG)을 생성합니다. NSG1을 서브넷1과 연결합니다.
인터넷 클라이언트가 App1에 접근할 수 있도록 해야 합니다. 솔루션은 다음 요구 사항을 충족해야 합니다.
* 네트워크 보안 규칙 변경을 최소화하십시오.
* 행정적 노력을 최소화합니다.
어떻게 해야 할까요? 정답을 선택하려면 답변란에서 적절한 옵션을 고르세요. 참고: 각 정답은 1점입니다.
Correct Answer:
Create an Azure load balancer named LB1, add VM1 to the backend pool, and then create a load balancing rule.
To NSG1, add an inbond rule that allows TCP 433 from the internet to LB1.
200台の仮想マシンを含むAzureサブスクリプションがあります
Azure Network Watcher を使用して、最も多くのネットワークトラフィックを生成している仮想マシンを特定する必要があります。このソリューションは、管理作業を最小限に抑える必要があります。
Network Watcher にどのような前提条件を展開する必要がありますか。また、仮想マシンを識別するためにどの Network Watcher 機能を使用する必要がありますか。回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:
VMSS1 という仮想マシン スケール セットと LB1 というパブリック標準 Azure ロード バランサーを含む Azure サブスクリプションがあります。VMSS1 には、プライベート IP アドレスのみを持つ 8 台の仮想マシンが含まれており、VMSS1 は LB1 のバックエンド プールとして構成されています。LB1 には 2 つのフロントエンド IP アドレスと、VMSS1 へのインターネット接続を提供する 1 つの送信規則があります。
VMSS1 内の仮想マシンで使用できるポートの最大数はいくつですか。また、VMSS1 で使用できる SNAT ポートの最大数を増やすには、何を変更する必要がありますか。回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:
1,000 台の仮想マシンを含む Azure サブスクリプションがあります。
ネットワーク セキュリティ グループ (NSG) フロー ログを収集します。
過去 30 日間に Azure 以外のパブリック IP アドレスとやり取りしたすべての仮想マシンを特定する必要があります。クエリをどのように完了する必要がありますか? 回答するには、回答領域で適切なオプションを選択します。注: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:
次の表に示すサイトを含むオンプレミス ネットワークがあります。

各サイトはファイアウォールを介してインターネットに接続されています。すべてのサイトはSD-WANに接続されています。各サイトはBGPを使用してルートを伝播するように構成されています。
Gateway 1 という名前の仮想ネットワーク ゲートウェイが含まれる Vnet1 という名前の仮想ネットワークを含む Azure サブスクリプションがあります。
ゲートウェイの図に示されている構成を使用して、ローカル ネットワーク ゲートウェイを作成します ([ゲートウェイ] タブをクリックします)。

接続図に示す構成で、サイト間(S2S)接続を作成します。(「接続」タブをクリックします)

次の各文について、正しい場合は「はい」を選択し、そうでない場合は「いいえ」を選択します。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:
会社には、IP アドレス空間 192.168.0.0/20 を使用する Vnet1 という名前の Azure 仮想ネットワークがあります。
Vnet1 には、IP アドレス空間 192.168.0.0/24 を使用する Subnet1 という名前のサブネットが含まれています。
/48 の CIDR サフィックスを使用して、Vnet1 への IPv6 アドレス範囲を作成します。
サブネット1上の仮想マシンが、会社から割り当てられたIPv6アドレスを使用して相互通信できるようにする必要があります。このソリューションでは、追加のIPv4アドレスの数を最小限に抑える必要があります。
どうすればいいでしょうか? 回答するには、回答エリアで適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:

Reference:
https://docs.microsoft.com/en-us/azure/virtual-network/ipv6-overview
https://docs.microsoft.com/en-us/azure/virtual-network/ipv6-add-to-existing-vnet-powershell
1) Correct: /64
Explanation: The subnets for IPv6 must be exactly /64 in size. This ensures future compatibility should you decide to enable routing of the subnet to an on-premises network since some routers can only accept /64 IPv6 routes.
Source: https://docs.microsoft.com/en-us/azure/virtual-network/ip-services/ipv6-overview
2) Correct: Public IPv6 Address
Explanation: Add IPv6 configuration to NIC. " Configure all of the VM NICs with an IPv6 address using Add- AzNetworkInterfaceIpConfig " Source: https://docs.microsoft.com/en-us/azure/load-balancer/ipv6-add-to-existing-vnet-powershell
Vnet2とVnet3にデフォルトルートを設定する必要があります。ソリューションは仮想ネットワークの要件を満たしている必要があります。
デフォルトルートを構成するには何を使用すればよいですか?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Azure Front Door に Azure Web アプリケーション ファイアウォール (WAF) のインスタンスがあります。
単一の IP アドレスからの高レートのリクエストをブロックする WAF ルールを作成する予定です。
ルールの最適なしきい値を特定するには、Log Analytics にクエリを実行する必要があります。
Log Analytics でクエリを実行する必要があるテーブルはどれですか?

Correct Answer: C Vote an answer
オンプレミス ネットワークでは、10.1.0.0 ~ 10.1.255.255 の IP アドレス範囲が使用されます。
次の要素を含む新しい Azure 仮想ネットワーク ソリューションを展開する予定です。
* VNet1という名前の仮想ネットワーク
* VNet1 とオンプレミス ネットワーク間のサイト間 (S2S) VPN 接続
* VNet1 の GatewaySubnet(ルートベースの仮想ネットワークゲートウェイとして使用) VNet1 と GatewaySubnet に割り当てるサブネットマスクを推奨する必要があります。ソリューションは以下の要件を満たす必要があります。
* VNet1 で使用可能な IP アドレスの数を最大化します。
* GatewaySubnetで利用可能なIPアドレスの数を最小限に抑える
VNet1 と GatewaySubnet に割り当てるアドレス空間はどれですか? 回答するには、回答領域で適切なオプションを選択してください。
注意: 正しい選択ごとに 1 ポイントが加算されます。
Correct Answer:

Explanation:
タスク4
10.1.1.0/24 の範囲の IP アドレスと storage34280945.pnvatelinlcblob.core.windows.net という名前を使用して、storage34280945 ストレージ アカウントへの接続が可能であることを確認する必要があります。
Correct Answer:
See the Explanation below for step by step instructions.
Explanation:
Here are the steps and explanations for ensuring that connections to the storage34280945 storage account can be made by using an IP address in the 10.1.1.0/24 range and the name stor-age34280945.pnvatelinlcblob.core.
windows.net:
To allow access from a specific IP address range, you need to configure the Azure Storage firewall and virtual network settings for your storage account. You can do this in the Azure portal by selecting your storage account and then selecting Networking under Settings1.
On the Networking page, select Firewalls and virtual networks, and then select Selected networks under Allow access from1. This will block all access to your storage account except from the networks or resources that you specify.
Under Firewall, select Add rule, and then enter 10.1.1.0/24 as the IP address or range. You can also enter an optional rule name and description1. This will allow access from any IP address in the 10.1.1.0/24 range.
Select Save to apply your changes1.
To map a custom domain name to your storage account, you need to create a CNAME record with your domain provider that points to your storage account endpoint2. A CNAME record is a type of DNS record that maps a source domain name to a destination domain name.
Sign in to your domain registrar's website, and then go to the page for managing DNS settings2.
Create a CNAME record with the following information2:
Source domain name: stor-age34280945.pnvatelinlcblob.core.windows.net
Destination domain name: stor-age34280945.pnvatelinlcblob.core.windows.net Save your changes and wait for the DNS propagation to take effect2.
To register the custom domain name with Azure, you need to go back to the Azure portal and select your storage account. Then select Custom domain under Blob service2.
On the Custom domain page, enter stor-age34280945.pnvatelinlcblob.core.windows.net as the custom domain name and select Save2.

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어